Hacker News new | ask | show | jobs
by bruce511 1069 days ago
I did exactly the same for our local-cloud products.

Our local-cloud program connects to our "certificate server", and asks for a name/ip combination.

Our certificate server gets it using API access to our "local-cloud" domain. The local machine receives it.

So the end user does not have the Domain credentials. They have credentials to our cert server, but those have very limited value (and would need to be decrypted first.)